惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
A
About on SuperTechFans
J
Java Code Geeks
G
Google Developers Blog
L
LangChain Blog
小众软件
小众软件
宝玉的分享
宝玉的分享
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
博客园 - 【当耐特】
IT之家
IT之家
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
博客园 - Franky
博客园_首页
雷峰网
雷峰网
Microsoft Security Blog
Microsoft Security Blog
Vercel News
Vercel News
B
Blog
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
2 Scattered Spider-Linked Hackers Plead Guilty Over £39M ...
Deeba Ahmed · 2026-06-23 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Two young hackers, reportedly the members of the Scattered Spider hacking group, pleaded guilty under the Computer Misuse Act for their involvement in a £39 million cyberattack on Transport for London (TfL). Specifically, they admitted to conspiring to commit unauthorised acts against TfL’s computer systems, a charge carrying a severe warning that the attack created a serious risk of damage to human welfare.

The hackers, Thalha Jubair, 20, and Owen Flowers, 18, were to stand trial at Woolwich Crown Court on 22 June, but they changed their pleas to guilty on the very first day of their trial.

“The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries, epitomised by Scattered Spider,” NCA’s deputy director and NCA’s National Cyber Crime Unit, Paul Foster, stated in an official press release.

Jubair and Flowers are accused of a cyberattack on TFL between 31 August and 3 September 2024 that completely shook the capital’s transport network, causing a 3-month-long service disruption, even forcing all 28,000 TfL staff members to physically walk into an office just to reset their computer passwords.

The attack hit everyday passengers harder because the hackers also targeted the Oyster card refund system. This forced people to wait much longer to get their money back. Also, the hackers completely shut down the online application system for children’s discount Oyster cards. The British Transport Police and West Midlands officers collaborated to arrest the hackers after a “lengthy, highly complex and painstaking investigation,” the NCA’s official statement read.

As per Hackread.com’s past coverage of the incident in September 2024, while core train and bus services remained running, the hackers did access the personal details, names, and bank information of 10 million customers.

Two UK Hackers Plead Guilty to £39 Million Cyberattack on Transport for London
Thalha Jubair, 20 (left) and Owen Flowers, 18 (right).

Raids and International Targets

The National Crime Agency (NCA) and City of London Police raided the hackers’ homes on 16 September 2024, seizing tower computers, laptops, USB sticks, and hard drives containing crucial evidence linking the duo to the attack.

One laptop had video clips of Jubair actually using TfL systems while the two discussed the attack on Telegram and a shared online workspace. Flowers also looked at data, selling stolen login details online, and broke his bail rules twice in 2025. He even targeted US hospitals, breaking into networks belonging to SSM Health Care and Sutter Health.

Teenagers and Online Crime

This case highlights the consistent, disturbing rise in the youth’s involvement in such crimes, as they don’t understand the legal dangers of cyberattacks. NCA earlier reported that one in five UK children between 10 and 16 have broken the law online and engaged in hacking.

“A recent survey of children aged 10-16 showed that 20% engage in behaviours that violate the Computer Misuse Act, which criminalises unauthorised access to computer systems and data. The figure is higher for those who game, standing at 25%,” NCA reported in 2024.

The case against Jubair and Flowers actually shows what happens when authorities catch these young hackers, and it must be taken as an example. Now that they have pleaded guilty, both will remain in custody. They will face the legal consequences together during a two-day sentencing hearing scheduled for 15 and 16 July 2026.